Splunk Search

Can you help me come up with a regex for an API path?

Hi Community,

Sorry this should be easiest for you, but i have many problem with regex ....

i want to keep the first 3 sets of information (bellow in red)

alt text

i have already done this :

" |rex field=uri_path "^/(?\w+)" |

but i have only the first.

Can you help me ?

Tags (2)
0 Karma
1 Solution

Path Finder

this should work:

  | rex field=uri_path "^(?<myfield>/\w+/\w+/\w+/)"

View solution in original post

0 Karma

Path Finder

this should work:

  | rex field=uri_path "^(?<myfield>/\w+/\w+/\w+/)"

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

Hi,

You can use below regular expression to extract those values

<yourBaseSearch> | rex field=uri_path "^(?<extracted_uri>\/\w+\/\w+\/\w+\/?)"
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!